<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco SAL on Prem in Security Analytics</title>
    <link>https://community.cisco.com/t5/security-analytics/cisco-sal-on-prem/m-p/4948394#M1000</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have try to connect my ASA5555 FTD6.4 on FMC for sent syslog to SAL (On Prem) on SNA in manager only mode. As I research If I use SNA manager to install SAL&amp;nbsp;(On Prem) that didn't required CDO, Is it?&lt;/P&gt;
&lt;P&gt;I have followed&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/sal-on-prem/integration/csal_op_app_3_2_0_deploy_guide/m_csal_op_deploy_steps_v32.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/sal-on-prem/integration/deployment_guide/csal_op_for_fmc_7_0_deploy_guide.pdfhttps://www.cisco.com/c/en/us/td/docs/security/sal-on-prem/integration/csal_op_app_3_2_0_deploy_guide/m_csal_op_deploy_steps_v32.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;by step&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;Install the Security Analytics and Logging (OnPrem) App&lt;/P&gt;
&lt;P&gt;For Managed Devices Running Versions Earlier than 7.0, Use Syslog&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;Configure Firepower Threat Defense Settings to Export syslog to Secure Network Analytics&lt;/P&gt;
&lt;P&gt;- Enable Connection Event Logging to syslog per Access Control Rule&lt;/P&gt;
&lt;P&gt;- On my SAL (On Prem) I'm still have no logging.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and there is my FTD&lt;/P&gt;
&lt;P&gt;firepower# sh run logging&lt;BR /&gt;logging enable&lt;BR /&gt;logging timestamp rfc5424&lt;BR /&gt;logging emblem&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class auth&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class vpn&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class vpnc&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class vpnfo&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class vpnlb&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class webfo&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class webvpn&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class ca&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class svc&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class ssl&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class dap&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class ipaa&lt;BR /&gt;logging FMC MANAGER_VPN_EVENT_LIST&lt;BR /&gt;logging host ngfw-management 192.168.2.177 17/8514 format emblem&lt;BR /&gt;logging permit-hostdown&lt;BR /&gt;no logging message 106015&lt;BR /&gt;no logging message 313001&lt;BR /&gt;no logging message 313008&lt;BR /&gt;no logging message 106023&lt;BR /&gt;no logging message 710003&lt;BR /&gt;no logging message 302015&lt;BR /&gt;no logging message 302014&lt;BR /&gt;no logging message 302013&lt;BR /&gt;no logging message 302018&lt;BR /&gt;no logging message 302017&lt;BR /&gt;no logging message 302016&lt;BR /&gt;no logging message 302021&lt;BR /&gt;no logging message 302020&lt;BR /&gt;firepower#&lt;/P&gt;
&lt;P&gt;Am I missed some process? I have try to find and research some information about SAL (On Prem) but I'm only see about SaaS with CDO.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 26 Oct 2023 06:47:00 GMT</pubDate>
    <dc:creator>nichamon</dc:creator>
    <dc:date>2023-10-26T06:47:00Z</dc:date>
    <item>
      <title>Cisco SAL on Prem</title>
      <link>https://community.cisco.com/t5/security-analytics/cisco-sal-on-prem/m-p/4948394#M1000</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have try to connect my ASA5555 FTD6.4 on FMC for sent syslog to SAL (On Prem) on SNA in manager only mode. As I research If I use SNA manager to install SAL&amp;nbsp;(On Prem) that didn't required CDO, Is it?&lt;/P&gt;
&lt;P&gt;I have followed&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/sal-on-prem/integration/csal_op_app_3_2_0_deploy_guide/m_csal_op_deploy_steps_v32.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/sal-on-prem/integration/deployment_guide/csal_op_for_fmc_7_0_deploy_guide.pdfhttps://www.cisco.com/c/en/us/td/docs/security/sal-on-prem/integration/csal_op_app_3_2_0_deploy_guide/m_csal_op_deploy_steps_v32.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;by step&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;Install the Security Analytics and Logging (OnPrem) App&lt;/P&gt;
&lt;P&gt;For Managed Devices Running Versions Earlier than 7.0, Use Syslog&lt;/P&gt;
&lt;P&gt;-&amp;nbsp;Configure Firepower Threat Defense Settings to Export syslog to Secure Network Analytics&lt;/P&gt;
&lt;P&gt;- Enable Connection Event Logging to syslog per Access Control Rule&lt;/P&gt;
&lt;P&gt;- On my SAL (On Prem) I'm still have no logging.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and there is my FTD&lt;/P&gt;
&lt;P&gt;firepower# sh run logging&lt;BR /&gt;logging enable&lt;BR /&gt;logging timestamp rfc5424&lt;BR /&gt;logging emblem&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class auth&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class vpn&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class vpnc&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class vpnfo&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class vpnlb&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class webfo&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class webvpn&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class ca&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class svc&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class ssl&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class dap&lt;BR /&gt;logging list MANAGER_VPN_EVENT_LIST level informational class ipaa&lt;BR /&gt;logging FMC MANAGER_VPN_EVENT_LIST&lt;BR /&gt;logging host ngfw-management 192.168.2.177 17/8514 format emblem&lt;BR /&gt;logging permit-hostdown&lt;BR /&gt;no logging message 106015&lt;BR /&gt;no logging message 313001&lt;BR /&gt;no logging message 313008&lt;BR /&gt;no logging message 106023&lt;BR /&gt;no logging message 710003&lt;BR /&gt;no logging message 302015&lt;BR /&gt;no logging message 302014&lt;BR /&gt;no logging message 302013&lt;BR /&gt;no logging message 302018&lt;BR /&gt;no logging message 302017&lt;BR /&gt;no logging message 302016&lt;BR /&gt;no logging message 302021&lt;BR /&gt;no logging message 302020&lt;BR /&gt;firepower#&lt;/P&gt;
&lt;P&gt;Am I missed some process? I have try to find and research some information about SAL (On Prem) but I'm only see about SaaS with CDO.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2023 06:47:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/cisco-sal-on-prem/m-p/4948394#M1000</guid>
      <dc:creator>nichamon</dc:creator>
      <dc:date>2023-10-26T06:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco SAL on Prem</title>
      <link>https://community.cisco.com/t5/security-analytics/cisco-sal-on-prem/m-p/5308377#M1208</link>
      <description>&lt;P&gt;You do not need Cisco Defense Orchestrator (CDO) to use SAL On-Prem with FMC-managed FTDs, especially in Manager-Only mode (no Flow Collectors). This is a valid, supported deployment model.&lt;/P&gt;&lt;P&gt;The confusion comes from most public materials emphasizing the SaaS/Cisco Cloud integration (SAL via CDO). But the On-Prem SAL is fully valid on its own.&lt;/P&gt;&lt;P&gt;Goal Recap&lt;BR /&gt;You're trying to:&lt;/P&gt;&lt;P&gt;Send connection events from FTD 6.4.x to SAL On-Prem&lt;/P&gt;&lt;P&gt;Using syslog, because FTD &amp;lt;7.0 does not support eStreamer to SAL&lt;/P&gt;&lt;P&gt;Using the Manager-only deployment of SAL (no Flow Collectors, just logs)&lt;/P&gt;&lt;P&gt;You're not seeing logs appear in SAL On-Prem&lt;/P&gt;&lt;P&gt;Steps to Confirm / Review&lt;BR /&gt;Let's go through what must be in place.&lt;/P&gt;&lt;P&gt;1. SAL On-Prem Installed on SNA Manager&lt;BR /&gt;Ensure you followed the correct document:&lt;/P&gt;&lt;P&gt;You’re using this guide: SAL On-Prem for FMC 7.0 and earlier&lt;/P&gt;&lt;P&gt;Key things to confirm:&lt;/P&gt;&lt;P&gt;The SAL On-Prem App is installed and listed under System → Settings → Applications&lt;/P&gt;&lt;P&gt;The SAL app is configured to listen on UDP 8514&lt;/P&gt;&lt;P&gt;Firewall/SELinux is not blocking 8514/UDP&lt;/P&gt;&lt;P&gt;2. FTD Syslog Config&lt;BR /&gt;Your syslog output:&lt;/P&gt;&lt;P&gt;bash&lt;BR /&gt;Copy&lt;BR /&gt;Edit&lt;BR /&gt;logging enable&lt;BR /&gt;logging host ngfw-management 192.168.2.177 17/8514 format emblem&lt;BR /&gt;This looks correct if 192.168.2.177 is the SNA Manager (SAL App host).&lt;/P&gt;&lt;P&gt;BUT also verify:&lt;/P&gt;&lt;P&gt;FTD is using the correct syslog format for SAL:&lt;/P&gt;&lt;P&gt;For FTD &amp;lt;7.0, emblem + correct message IDs are needed.&lt;/P&gt;&lt;P&gt;Only certain syslog messages will be parsed by SAL.&lt;/P&gt;&lt;P&gt;Missing step: You need to enable logging in the Access Control Policy (ACP):&lt;/P&gt;&lt;P&gt;In FMC:&lt;/P&gt;&lt;P&gt;Go to Policies → Access Control Policy&lt;/P&gt;&lt;P&gt;Open the ACP applied to this FTD&lt;/P&gt;&lt;P&gt;Under each rule, check:&lt;/P&gt;&lt;P&gt;Log at end of connection&lt;/P&gt;&lt;P&gt;Send to Syslog&lt;/P&gt;&lt;P&gt;Set logging level (Informational or higher)&lt;/P&gt;&lt;P&gt;Without this, the FTD won’t send connection events to SAL.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":small_blue_diamond:"&gt;🔹&lt;/span&gt; 3. SAL Parsing &amp;amp; Syslog Verification&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; On your SNA Manager (hosting SAL), verify that logs are arriving at the SAL app:&lt;/P&gt;&lt;P&gt;bash&lt;BR /&gt;Copy&lt;BR /&gt;Edit&lt;BR /&gt;sudo tcpdump -nn udp port 8514&lt;BR /&gt;You should see traffic from your FTD. If not, FTD is not sending or network is blocking.&lt;/P&gt;&lt;P&gt;4. View SAL Dashboard&lt;BR /&gt;Log into the SNA Manager Web UI&lt;/P&gt;&lt;P&gt;Go to Applications → Security Analytics and Logging&lt;/P&gt;&lt;P&gt;You should see:&lt;/P&gt;&lt;P&gt;A dashboard showing "Events received"&lt;/P&gt;&lt;P&gt;Charts with Connection Events, Top Apps, etc.&lt;/P&gt;&lt;P&gt;If not:&lt;/P&gt;&lt;P&gt;Check the SAL logs:&lt;/P&gt;&lt;P&gt;bash&lt;BR /&gt;Copy&lt;BR /&gt;Edit&lt;BR /&gt;sudo docker logs --tail=100 -f sal&lt;BR /&gt;Look for parsing errors or connectivity issues.&lt;/P&gt;&lt;P&gt;Summary of What May Be Missing&lt;BR /&gt;Step Status&lt;BR /&gt;SAL On-Prem app installed on SNA Manager &lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; You did this&lt;BR /&gt;Syslog listener (UDP 8514) configured &lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; Appears correct&lt;BR /&gt;FTD syslog enabled and pointing to SAL &lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; Correct syntax&lt;BR /&gt;ACP rules logging to syslog enabled &lt;span class="lia-unicode-emoji" title=":warning:"&gt;⚠️&lt;/span&gt; Often missed&lt;BR /&gt;SAL logs parsed successfully &lt;span class="lia-unicode-emoji" title=":question_mark:"&gt;❓&lt;/span&gt; Check via docker logs sal&lt;BR /&gt;Syslog received (tcpdump on port 8514) &lt;span class="lia-unicode-emoji" title=":question_mark:"&gt;❓&lt;/span&gt; Check with tcpdump&lt;/P&gt;&lt;P&gt;Next Actions&lt;BR /&gt;Confirm “Log at end of connection → Send to Syslog” is enabled in ACP rules on FMC.&lt;/P&gt;&lt;P&gt;On SAL Manager:&lt;/P&gt;&lt;P&gt;Run tcpdump to confirm logs are arriving&lt;/P&gt;&lt;P&gt;Check SAL app logs via Docker for errors&lt;/P&gt;&lt;P&gt;In SNA Web UI → Applications → SAL, check for any events being processed&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2025 16:03:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/cisco-sal-on-prem/m-p/5308377#M1208</guid>
      <dc:creator>wajidhassan</dc:creator>
      <dc:date>2025-07-11T16:03:25Z</dc:date>
    </item>
  </channel>
</rss>

